Information Flow Control for Static Enforcement of User-Defined Privacy Policies

Information Flow Control for Static Enforcement of User-Defined Privacy Policies
复制标题

用于静态执行用户定义的隐私策略的信息流控制

DOI:
10.1109/policy.2011.23
复制
发表时间:
2011
期刊:
2011 IEEE International Symposium on Policies for Distributed Systems and Networks
影响因子:
--
通讯作者:
Sören Preibusch
Sören Preibusch
中科院分区:
--
文献类型:
--
作者:
Sören Preibusch

文献摘要

被引文献

相似文献

信息流控制 (IFC) 允许软件程序员和审计员检测并防止程序不同部分之间的信息共享,从策略上讲,这些信息应该在逻辑上保持独立。然而,IFC 缺乏广泛使用表明其采用存在技术和可用性障碍。编程语言 JIF 在 Java 之上提供了 IFC。为了评估将 JIF 用于商业隐私保护 Web 应用程序的实用问题和系统限制,我们提供了第一个基于 Web 的案例研究,其中包含客户协商的数据接收者和使用限制。在实践层面上,根据我们在 JIF 中进行编程的经验,我们评估了其对于防止意外滥用个人信息的适用性,并为未来的实施提出了建议。在理论层面上,我们探讨了静态分析和运行时配置的隐私策略之间的兼容性。
Information flow control (IFC) allows software programmers and auditors to detect and prevent the sharing of information between different parts of a program which, as a matter of policy, should be kept logically separate. However, the lack of widespread use of IFC suggests technology and usability barriers to adoption. The programming language JIF provides IFC on top of Java. To assess pragmatic issues and systematic limitations of using JIF for commercial privacy-preserving Web applications, we deliver the first Web-based case-study with customer-negotiated restrictions on data recipients and usage. On a practical level, from our experience of programming in JIF, we assess its suitability for preventing accidental misuse of personal information and deduce recommendations for future implementations. On a theoretical level, we explore the compatibility between static analysis and privacy policies configured at runtime.